gweh88x[.]life
“gweh88x.life”
gweh88x.life — Неперевірений. Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_SPAM; PhishDestroy score 71/100. Реєстратор: URL Solutions.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain gweh88x.life was registered on February 21, 2026 through URL Solutions, Inc. and is presently active. The site returns an HTTP 200 response and presents a page title identical to the domain name, a pattern frequently observed in credential‑phishing operations. Two of ninety‑five security vendors on VirusTotal have flagged the domain, and it appears on a single external blocklist. PhishDestroy has already listed the host as malicious, reinforcing the consensus that the site is being used for phishing. The overall risk rating is high, and the Gridinsoft trust score of 0 out of 100 reflects a complete lack of reputation.
Infrastructure analysis shows the domain resolves to the IP address 91.215.43.30, which is hosted in Russia and associated with Ddos‑guard LTD. The SSL certificate presented is labeled “R11,” indicating the use of a self‑signed or low‑trust certificate that does not provide meaningful encryption assurances. Four nameservers—ns1.pananames.com, ns2.pananames.com, ns3.pananames.com, and ns4.pananames.com—are configured for the domain, a common setup for rapidly provisioned malicious sites that rely on generic DNS services. No additional infrastructure details such as ASN or CDN usage are disclosed, leaving the precise hosting environment uncertain.
The evidence points to a credential‑phishing campaign targeting users who may be lured by the domain’s innocuous appearance. The combination of a newly created domain, a low‑trust SSL certificate, a Russian‑based IP address, and active blocklist entries aligns with known tactics used by phishing actors to harvest login credentials. Defenders should block the domain at the DNS and proxy layers, monitor outbound traffic for connections to 91.215.43.30, and update email filtering rules to flag any messages containing links to gweh88x.life. Continuous observation of the associated nameservers is advised, as they may be reused for future malicious domains.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога